CVE-2026-40687

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.

medium 4.8 CVSS 3.1
Published: Apr 30, 2026
Modified: May 1, 2026
Vendor: Exim
Product: Exim